This is not to excuse Microsoft, they could certainly do better. But so could Apple and Debian.
I think there's a lot to be said for those who practice what they preach rather than sticking with a lesser option out of convenience.
I'd suggest that by using a platform that he knows how to make secure rather than one he's unfamiliar with, he is acting in the best way to ensure the security of his device.
Also there are very good reasons for using windows - dogfooding your own security solutions, fact that a lot of threats are targeting windows machines and the fact that he is not a high profile target (or wasn't before the NSA stuff) so no one will waste undisclosed zero day on him.
Against the US? I doubt it. Countries sometimes fail to treat actual armed intrusions without local consent by the US as casus belli because of the imbalance in military power, and you want me to believe that there are "a lot" of countries that will treat a backdoor in Windows as an excuse for war?
The second suggestion being they (the NSA) have a (likely lengthy) list of exploits found in common OSes (and/or firmware or CPU microcode) that they have never divulged and that they have discovered like any external security research would have (albeit one with a very large budget and a very strong incentive to find such control vectors).
I prefer to assume that both are true.